ZeroHour
Infosecurity Magazinepublished ()ingested Kevin Poireault

Rust Payloads Exploiting Ivanti 0

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-21887
+1 in the same advisory: …46805
Command Injection RCE in Ivanti Connect Secure and Policy Secure

Ivanti Connect Secure (formerly Pulse Connect Secure) and Ivanti Policy Secure appliances contain a command injection flaw (CWE-77) in their web components, triggered when an authenticated administrator sends crafted requests to the appliance. The bug can be chained with the separate authentication bypass CVE-2023-46805, allowing an unauthenticated attacker to achieve the same result. Successful exploitation lets an attacker execute arbitrary commands and code on the appliance, providing a foothold into the networks behind the VPN or network access control gateway. Any organization running these appliances, typically enterprises and government agencies often deployed directly on the internet perimeter, is affected. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-10 with known ransomware use and EPSS assigns a 100% probability of exploitation within 30 days, although no public proof-of-concept is available.

Do: Apply Ivanti's mitigations or patched builds immediately per vendor instructions, addressing the chained authentication bypass CVE-2023-46805 at the same time, and discontinue or restrict use of any appliance for which mitigations are unavailable, especially if it is internet-facing. Because exploitation with ransomware use is known, assume compromise is possible: review appliance web logs for suspicious requests and run Ivanti's integrity-checking guidance to verify appliance images before and after remediation. Where feasible, restrict direct internet exposure of the appliance web interface and monitor for further vendor advisories.

9.1
group max
100% KEV ransomware PoC
  • Ivanti Connect Secure (ICS, formerly Pulse Connect Secure)
  • Ivanti Policy Secure
largetens of thousands of appliances (roughly 20,000-30,000 internet-exposed ICS gateways at disclosure; total deployed base likely higher)
Full article355 words · extracted from infosecurity-magazine.com · click to collapse

Payloads recently found on compromised Ivanti Connect Secure appliances could be from the same, sophisticated threat actor, according to incident response provider Synacktiv.

A new malware analysis from Synacktiv researcher Théo Letailleur showed that the 12 Rust payloads discovered by Volexity as part of its investigation into two Ivanti Connect Secure VPN remote code execution (RCE) zero-days (CVE-2024-21887 and CVE-2023-46805) share almost 100% code similarity.

KrustyLoader Executes Sliver, A Cobalt Strike Alternative

The primary purpose of this string of payloads, which the researcher named “KrustyLoader,” is to download and execute a Sliver backdoor coded in Golang.

Sliver is a post-exploitation toolkit created by offensive security provider Bishop Fox to allow red teams to maintain access and control over a compromised system after gaining initial entry. It offers various capabilities, such as spying on a network, executing commands, spawning sessions, or loading reflective DLLs.

Sliver emerged as a popular choice for cybercriminals in the latter half of 2023 following a law enforcement operation attempting to shut down ‘cracked’ versions of Cobalt Strike, another offensive toolkit.

ConnectSecure Exploitation Shows APT-Level Sophistication

In his malware analysis, Letailleur found that these 12 payloads are interestingly sophisticated – they perform specific checks in order to run only if conditions are met, for instance.

This finding aligns with previous findings from Volexity and Mandiant, who both reported that an advanced persistent threat (APT) actor was behind some Ivanti zero-day exploitations.

Volexity attributed it to a Chinese-backed group tracked as UTA0178. Mandiant attributed it to an activity cluster it tracks as UNC5221.

US federal officials also said the attacks shared some similarities with the Volt Typhoon attacks linked to China during mid-2023.

Ivanti Patch Delayed

Ivanti has been working with Mandiant to mitigate the threat activity, which has led to the compromise of more than 2100 systems so far.

While a patch was initially scheduled for the week of January 22, Ivanti announced on January 26 that the release would be delayed to the week of January 30 at the earliest.

No patch is available at the time of writing.

Read more: CISA Emergency Directive Demands Action on Ivanti Zero-Days

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/rust-payloads-ivanti-zero-days/